Commit Graph
8 Commits
Author SHA1 Message Date
Dmitry Verenitsin 3630e3dd85 [core] Harden switch_b64_encode output bound (#3111)
switch_b64_encode wrote each base64 character before checking the
output bound, and computed that bound as `bytes >= (int)olen - 1`.
Both are unsafe:

- Writing before the check meant a buffer with no room for a data
  byte still received one: `olen == 1` wrote a character at index 0
  and the NUL at index 1, and `olen == 0` (where `(int)olen - 1` is
  -1) wrote two bytes, both past the end.
- Casting the unsigned `olen` to `int` truncated it above INT_MAX,
  producing a wrong bound for very large buffers.

Reject `olen == 0`, make the output index `bytes` a `size_t`, and test
`bytes + 1 >= olen` before each write, so the bound never casts or
underflows and always leaves the last byte for the terminator. Apply
the same `bytes + 1 < olen` guard to the trailing partial-group
character and the `=` padding, so no write can pass the end.

Remove the dead line-wrap counter `y`: it only gated a commented-out
newline emit, so it counted and reset with no effect on the output.

Add unit tests covering the output-bound edges for every write site.
2026-08-08 22:05:20 +03:00
Dmitry Verenitsin 394b48b9f5 [core] Harden switch_b64_decode output bound and input handling (#3110)
switch_b64_decode bounded its writes with `ol >= olen - 1`, where
`olen` is unsigned. An `olen` of 0 made `olen - 1` wrap to `SIZE_MAX`,
so the bound never fired and the loop wrote the entire decoded input
plus a trailing NUL past the destination. Reject `olen == 0` and test
`ol + 1 >= olen` before each write, so the comparison never subtracts
from an unsigned and always leaves room for the terminator.

The alphabet lookup table `l64` was a `char` indexed by a `char`,
which is unsafe whichever way `char` is signed:

- Where `char` is signed, an input byte >= 0x80 became a negative
  index and read before the table.
- Where `char` is unsigned, the `-1` "not in alphabet" sentinel was
  stored as 255, so the skip test never matched and non-alphabet
  bytes were folded in as data.

Make `l64` a `signed char` and index it with `(unsigned char)`, so the
sentinel survives and the index stays in range on every platform.

Change the bit accumulator `b` from `int` to `unsigned int` to avoid
signed-overflow undefined behavior on long input; decoded output is
unchanged.

Add unit tests: an encode/decode round-trip across the padding cases,
the output-bound edges (`olen` of 0, 1, and a truncating buffer), and
a non-alphabet byte (including one >= 0x80) that must be skipped.
2026-08-08 21:40:30 +03:00
Dmitry Verenitsin 325bb3a606 [core] Fix segments count check in clean_uri(). Add unit-test. (#3032) 2026-05-26 00:16:40 +03:00
Seven Du ef3bd2d8c3 [core] fix base64 decoded size when encoded string contains padding = 2024-10-09 22:53:00 +08:00
s3rj1k 91f12b5920 [Unit-tests] Fix previously defined AM_* in tests. 2021-02-23 20:59:26 +03:00
windy-wang 1d2a1057f8 [Core] Fix the null char in truncated value returned by switch_b64_decode 2020-09-01 21:04:49 +04:00
Andrey Volk 2865603ad2 [Unit-tests] Fix xml error not finding freeswitch.xml on FST_MINCORE_BEGIN 2019-11-26 01:54:43 +04:00
Seven Du 18940d13f1 FS-11455 add switch_utils test 2018-12-20 10:19:20 -05:00